Earlier quoted context omitted.
They enabled call forwarding and got Google to call with a password reset code.
Its not clear how they got his phone number though.
Even with 2FA, Google accounts can be hacked with just a phone number
61–70 of 128 posts
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#62Earlier quoted context omitted.
I thought that would be an answer, but then if your phone is stolen and they get in, couldn't they simply invalidate your 2fa codes too? Mind you, it's probably the best idea.
Simply stealing your phone isn't enough. They also need to know your password change 2-step settings.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#63Earlier quoted context omitted.
Backup codes.
It's also possible to install the seed for the TOPT generator on multiple devices - all the ones I've bumped into have a mechanism for typing in a long-ish string as well as scanning a QR code - record that string (secured like a password, in something like 1Password) and you can always re-seed another device to come up with the same codes. I've got all mine on two phones and a iPad - one of the phones is usually in…
Backup codes may be a good option if kept somewhere very safe.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#64Earlier quoted context omitted.
It's also possible to install the seed for the TOPT generator on multiple devices - all the ones I've bumped into have a mechanism for typing in a long-ish string as well as scanning a QR code - record that string (secured like a password, in something like 1Password) and you can always re-seed another device to come up with the same codes. I've got all mine on two phones and a iPad - one of the phones is usually in…
In my experience, when setting up a new device, you have to scan the QR or type in a code, then verify a generated key or two to "confirm" the new device. I'm not sure if that's an optional step, but it seems like you'd need to log in first, thus creating a chicken-egg situation for yourself. I'm sure you could enroll another device (e.g. tablet that always stays in the house, SO's phone, whatever), but it doesn't se…
I've got at least gmail, aws(/amazon), Github, Dropbox, Zoho, and several TOTP TFA protected WordPress sites on 3 different devices using this method. It definitely works. I see additional devices start to generate the same codes when I add the same seed (so long as their clocks are reasonable synced...)
This is using the Google Authenticatior app on iOS and Android, I _think_ any RFC6238 compliant TOTP app that lets you type in a string to key it should "just work".
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#65What strikes me most in these stories, is how you always have to find some higher ranking company employee through personal connections in order to get a tiny possibility to take your account back. These companies build on their users but, when their users need them, they betray them.
People need to be much more aware of the fact that you don't own your gmail address, or your Twitter/Facebook/LinkedIn/Instagram/whatever account. Those companies encourage people to build their reputations and networks and "personal brands" inside their walled gardens, while repeatedly demonstrating that they won't lift a finger to help protect the user's custodianship of "their" usernames. Unfortunately - when you…
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#661. Email account with 2FA 2. Email randomized password stored in PasswordDatabase 3. PasswordDatabase is stored in CloudDrive 4. CloudDrive randomized password stored in PasswordDatabase 5. CloudDrive with 2FA 6. PasswordDatabase secured by weak password 7. 2FA codes from 2FApp 8. PasswordDatabase, CloudDrive, Email only available together on devices with a human-friendly password. Those 3 and the 2FApp are all on th…
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#67Earlier quoted context omitted.
Simply stealing your phone isn't enough. They also need to know your password change 2-step settings.
So you also need to make sure that your phone's browser doesn't have your Google password stored, and/or your phone's storage is encrypted with a strong-enough key.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#681. Email account with 2FA 2. Email randomized password stored in PasswordDatabase 3. PasswordDatabase is stored in CloudDrive 4. CloudDrive randomized password stored in PasswordDatabase 5. CloudDrive with 2FA 6. PasswordDatabase secured by weak password 7. 2FA codes from 2FApp 8. PasswordDatabase, CloudDrive, Email only available together on devices with a human-friendly password. Those 3 and the 2FApp are all on th…
3 combined with 6 sounds like a recipe for disaster if someone manages to compromise your CloudDrive account (probably not by breaking the password, but by social engineering or a method similar to the one in this article). If they get that, they have your encrypted password database, and if that has a weak password... you're totally SOL. The password database's password is one you want to be /very/ strong.
Has any CloudDrive service been socially engineered? I didn't find any results in my rudimentary search.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#69Earlier quoted context omitted.
I would advise to have them write on the account that in no circumstance are they to authorize you without the passcode. This is the weakest part of the chain. We all forget our passwords.
Every cell phone carrier out there CAN NOT allow you to make changes to an account or get any personal information from an account without properly identifying yourself with an authorized name on the account, plus the last four of the account holders social OR an account PIN. If a customer can not provide these over the phone they need to visit a store with a photo ID matching the account holder to get access to the…
Personal aside: does anyone know if I could call Verizon support and ask them to require a specific passcode be used before accepting any call relating to my account? Before I call and ask, I'd like to know the odds of them actually agreeing and actually abiding by it.
Re: Even with 2FA, Google accounts can be hacked with just a phone number
#70This is precisely why I thought Digits was such a terrible idea (check my comment history, it's there.) SMS is so incredibly insecure that anyone relying on it should not consider themselves security savvy. SMS TFA is lipstick on a pig. Cellphones are so cheap these days, they should all come with a TFA app pre-installed. I'm also not too keen on websites making it so easy to change your username. The story of @N on…